← Back

Incsub

incsub

27 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Forminator
forminator
Hummingbird
hummingbird
Hustle
hustle

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Incsub
1Hummingbird
Jun 17, 2026
Apr 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capa...Show more
The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privilege users, such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Incsub
1Forminator
Jun 17, 2026
Nov 23, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
1Incsub
1Hustle
Nov 21, 2024
Mar 17, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI.
1Incsub
1Buddypress Activity Plus
Nov 21, 2024
Oct 7, 2019
N/A· v4
8.1 HIGH· v3
7.8 HIGH· v2
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
1Incsub
1Hustle
Jun 17, 2026
May 29, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execut...Show more
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting malicious code into a pop-up window. Successful exploitation grants an attacker with a right to execute malicious code on the administrator's computer through Excel functions as the plugin does not sanitize the user's input and allows insertion of any text.Show less
1Incsub
1Forminator
Jun 17, 2026
Mar 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
1Incsub
1Forminator
Jun 17, 2026
Mar 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.